SHINDO5
CAMPFIRE, Inc.
Financial & payment82,465recordsup to 225,846 people affected
POSSIBLE LEAKBank account / Postal addressUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Apr 3, 2026
- Detected
- Apr 2, 2026 22:00 JST
- Detection to disclosure
- 1 day
- Leak
- Leak possible
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityName
ContactAddress, Phone number, Email address
Financial & paymentBank account details
Account dataUser name
System & internalSome source code (may have been viewed)
Not leaked
- Credit card information not included
How many
- People up to 225,846 people
- Project owners (since February 2021) 120,929 records
- Backers 130,155 records
- User names only (to 5 March 2025) 1,282 records
- Records with bank account details 82,465 records
Who is affected
- Project owners
- Backers
Cause
Unauthorized access to a GitHub account used for system administration led to access to the database
Timeline
- Unauthorized access to the GitHub account detected and blocked
- Announced the GitHub access (no personal data leak confirmed at that time)
- Database access confirmed
- Announced possible exposure of up to 225,846 people and began notifying them
- Individuals notified
- Yokohama DeNA BayStars announced the impact on backers of its victory-parade crowdfunding
Response
- Blocked the entry point
- Forensic investigation
- Notified individuals
- Hotline
- Phishing warning
- Password reset
Blocked the account and investigated with outside experts; reported to the PPC and consulted police; notified affected people from 24 April and opened a hotline (0120-188-070) on 28 April; warned about phishing and password reuse
What you should do
- Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
- Don't open links in emails from this company. The apology email itself may be fake
- Treat refund or apology calls and texts as scams. Call back only on the number from the official site
- Watch for unexpected mail or invoices; your address is hard to change
- Check the company's notice to see if you're affected
Lessons for companies
- Don't keep ID or bank data: delete after checks or use a KYC provider
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Cybersecurity-jp.com News · Apr 9, 2026
- ITmedia NEWS News · Apr 24, 2026
- Security Measures Lab Researcher · May 22, 2026